Network Defense and Risk Assessment Fundamentals

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/19

flashcard set

Earn XP

Description and Tags

This set of vocabulary flashcards covers fundamental concepts of network defense, security goals, human error taxonomies, and risk assessment frameworks as discussed in the lecture.

Last updated 2:40 AM on 8/6/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

20 Terms

1
New cards

NIST

A standards institution for the United States that provides recommendations and suggestions for how to properly conduct risk assessment.

2
New cards

Assets

The specific things being protected within an organization, such as information, services, devices, and user accounts.

3
New cards

Confidentiality

A core security goal that ensures only the people who should be able to see specific information are able to see it.

4
New cards

Integrity

A security goal dedicated to making sure information hasn't been maliciously altered on its way to the user.

5
New cards

Availability

A core aspect of security focused on ensuring that systems are functional and usable for their designed purposes.

6
New cards

Authentication

The process of proving that a user is who they claim to be.

7
New cards

Authenticity

The assurance that a resource, such as a website, is genuine and is truly what it says it is.

8
New cards

Accountability

The practice of keeping a record of everything that happened in a system to facilitate future audits.

9
New cards

James Reason

The person credited with the taxonomy of human errors classified as slips, lapses, and mistakes.

10
New cards

Slips

A form of human error where the user has the right intention but fails to execute the action correctly, such as typing a wrong IP address.

11
New cards

Lapses

A type of human error where a user forgets to perform a necessary action, such as failing to turn security functionality back on after production.

12
New cards

Mistakes

Errors of intent where a user has a fundamental misunderstanding of what they are supposed to be doing, leading to a wrong plan.

13
New cards

Threat Events

Specific occurrences that can cause harm to assets, including phishing messages, malware, misconfigurations, floods, and disk failures.

14
New cards

Vulnerability

A weakness in defense, such as insufficient authentication, unpatched services, or a firewall that is too permissive.

15
New cards

Risk Formula

A simple teaching formula where risk is determined by: Impact×Likelihood\text{Impact} \times \text{Likelihood}.

16
New cards

Attack Surface

The total exposure or entry points to a network that an administrator must defend or attempt to reduce.

17
New cards

Predisposing Condition

A contextual amplifier on the harm a vulnerability can cause, such as a system being located in an environment prone to flooding.

18
New cards

Identify, Protect, Detect, Respond, Recover, Govern

The six functions or pillars that comprise the NIST Cybersecurity Framework.

19
New cards

IETF

The organization that comes up with RFCs which define various protocols at the internet level.

20
New cards

IEEE

The organization responsible for standardizing Ethernet, LAN, and WiFi controls.